Products: 1
    Vulnerabilities: 12
    Known Exploited: 0
    9
    Critical Level Threats
    2
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-41253

    Local Code Execution via SSH Conductor Escape Sequences in iTerm2

    Last Modified: Apr 20, 2026
    Published: Apr 18, 2026

    CVE-2025-22275

    iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.

    Last Modified: Jun 20, 2025
    Published: Jan 03, 2025

    CVE-2024-38396

    An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.

    Last Modified: Jun 20, 2025
    Published: Jun 16, 2024

    CVE-2024-38395

    In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."

    Last Modified: Jun 18, 2025
    Published: Jun 16, 2024

    CVE-2023-46321

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.

    Last Modified: Nov 21, 2024
    Published: Oct 22, 2023
    Items Per Page